Hi Guys -
I'm trying to remove "DEBUG" messages from ALL inputs. What do I put in props.conf to apply a transform to all incoming data - or am I going about this wrong?
Thanks!
-Mike
If this is really what you want to do, you can put it under the [default]
stanza in $SPLUNK_HOME/etc/system/local/props.conf
. This should cause your TRANSFORMS rule to fire for everything.
I am concerned it could wind up being overzealous, though. If your regex matches on just the word "DEBUG", it has a lot of chances for false positives and will also hit Splunk's _internal
index. Before doing this in production, test test test...
If this is really what you want to do, you can put it under the [default]
stanza in $SPLUNK_HOME/etc/system/local/props.conf
. This should cause your TRANSFORMS rule to fire for everything.
I am concerned it could wind up being overzealous, though. If your regex matches on just the word "DEBUG", it has a lot of chances for false positives and will also hit Splunk's _internal
index. Before doing this in production, test test test...
Thanks!!!!